Add V2 Importer for Tuxcare advisories#2104
Add V2 Importer for Tuxcare advisories#2104Samk1710 wants to merge 9 commits intoaboutcode-org:mainfrom
Conversation
vulnerabilities/tests/pipelines/v2_importers/test_tuxcare_importer_v2.py
Outdated
Show resolved
Hide resolved
|
@ziadhany Thanks for your review. |
|
@Samk1710, could you please also fix the CI ? |
|
Hey @ziadhany |
|
Hey @ziadhany |
|
Hey @ziadhany I have rectified the PURL. Also added more data to test each OS type with their respective PURLs. Kindly review the changes when you have time. Thanks. |
|
Hey @ziadhany |
0f27746 to
7d47d46
Compare
ziadhany
left a comment
There was a problem hiding this comment.
The code looks good, just a few nits.
| ) | ||
| ) | ||
|
|
||
| if severity and score and not severity_added: |
There was a problem hiding this comment.
What is the use of the severity_added variable? Why aren’t severity and score enough to add severity if it exists?
There was a problem hiding this comment.
Each CVE has only one severity score shared across all packages/distributions for that CVE, so we only want to add the severity once per advisory.
See: https://cve.tuxcare.com/els/cve?cve=CVE-2023-52922&os=&project=&version=&status=&after=&before=&orderBy=updated-desc
I have added a minor refactor and used if severity and score and not severities instead of the boolean.
Signed-off-by: Sampurna Pyne <sampurnapyne1710@gmail.com>
Signed-off-by: Sampurna Pyne <sampurnapyne1710@gmail.com>
Signed-off-by: Sampurna Pyne <sampurnapyne1710@gmail.com>
Signed-off-by: Sampurna Pyne <sampurnapyne1710@gmail.com>
Signed-off-by: Sampurna Pyne <sampurnapyne1710@gmail.com>
Signed-off-by: Sampurna Pyne <sampurnapyne1710@gmail.com>
Signed-off-by: Sampurna Pyne <sampurnapyne1710@gmail.com>
Signed-off-by: Sampurna Pyne <sampurnapyne1710@gmail.com>
Signed-off-by: Sampurna Pyne <sampurnapyne1710@gmail.com>
e4e1684 to
66be491
Compare
Thanks @ziadhany |
Addresses Issue:
Data Source: https://cve.tuxcare.com/els/download-json?orderBy=updated-desc
Importer Log Excerpt: